Adding a Palo Alto Device as a Proxied Device
Shows how to add a Palo Alto firewall as a proxied device in Netwrix Change Tracker. Covers SSH credential prerequisites, prompt regex configuration, and the login script directives current Gen 7 agents require.
Adding Antivirus Exclusions for Netwrix Change Tracker
Antivirus and endpoint detection and response (EDR) exclusions required for Netwrix Change Tracker agents and Hub to avoid performance degradation.
Adding or Replacing Configuration and Compliance Report Templates
Use this article when you have replaced or edited a configuration or compliance report template and need to upload it to Netwrix Change Tracker. It covers uploading templates, overwriting defaults, and assigning templates to device groups.
Applying a Compliance Template to a Group for Automated Reporting
Step-by-step instructions to apply a compliance template to a group in Netwrix Change Tracker for automated reporting.
Configuring FAST in Netwrix Change Tracker
Configuring File Approved Safe Technology (FAST) in Netwrix Change Tracker by creating a Planned Change rule set with a FAST Match rule.
Configuring In-Transit and At-Rest Data Encryption
Supported TLS versions for in-transit encryption and MongoDB at-rest encryption options for Netwrix Change Tracker.
Configuring Recursive File Content Monitoring
Shows how to enable recursive file content monitoring by editing the Change Tracker web server configuration and applying the filter to a configuration template in Netwrix Change Tracker.
Creating a Custom Tracked Attributes Filter Within a Configuration Template
Shows how to create a custom tracked attributes filter within a Netwrix Change Tracker configuration template when no default filter matches your requirements.
Determining Which Network Ports Need to Be Open
Describes which network ports to open to allow Netwrix Change Tracker agents and servers to communicate, including ports for agentless monitoring and network device configuration.
Disabling 2FA for the Default Administrator
Describes how to disable two-factor authentication (2FA) for the default administrator user in Netwrix Change Tracker so one-time codes are written to the server log for Allowed Commands.
Enabling Account Lockout for Failed Login Attempts
Shows how to configure Netwrix Change Tracker to lock a user account after repeated failed login attempts, by setting lockoutenabled to true in appsettings.json. This overrides the previous IP-blocking behavior, which is no longer used.
Excluding or Editing Information from Process Output Tracking (Agentless)
Shows how to exclude or edit lines from process output tracking on agentless devices using the ExcludeMatchesWithComment login script directive, so that always-changing values such as uptime do not generate change events.
Exporting Events from the Events Page to CSV, PDF, or XLSX
Exporting events from the Netwrix Change Tracker Events page to CSV, PDF, or XLSX format.
How to Change the Location of the Express Agent's Database and Log Files
Use the ConfigPath switch in expressAgent.ini to change the Express Agent database and log files location on Netwrix Change Tracker.
How to Configure the FAST Cloud Integration with Proxy Internet Settings
If you use a proxy on your Netwrix Change Tracker Server and FAST Cloud does not work, configure the proxy for IIS processes by adding a system environment variable. This article shows the exact steps to set the ALL_PROXY variable.
How to Upload a Compliance/Tracking Template to Change Tracker
This article shows how to upload a compliance/tracking template to Netwrix Change Tracker using the Settings > Policy Templates page, with step-by-step instructions.
Increasing File Content Max for Extension
Instructions to increase the File Content Max for extension setting on the Netwrix Change Tracker agent when file contents are not tracked because a file exceeds the configured size limit.
Increasing File Hash Max for Extension
Instructions to increase the File Hash Max for extension setting on the Netwrix Change Tracker agent when a file hash is not calculated because a file exceeds the configured size limit.
Monitoring Oracle Databases Using Change Tracker
How to configure Netwrix Change Tracker to monitor Oracle databases. This article covers required connection details, creating database credentials, proxy device setup, running test compliance reports, and common Oracle error troubleshooting.
Preventing Change Tracker from Recreating Deleted Default Groups
Preventing Netwrix Change Tracker from recreating default OS groups after deletion by adding the CreateDefaultGroups configuration item.
Re-Registering a Deleted Device on Change Tracker
Re-registering a device that was previously deleted from Netwrix Change Tracker using the Agents and Devices settings page.
Resetting the Default Admin Password
Instructions to reset the default admin password on Netwrix Change Tracker when the reset API is accessible only from the localhost on the Hub server.
Resubmitting a Group of Unplanned Changes
Using the Planned Change Wizard to create a planned change schedule and resubmit unplanned events in bulk in Netwrix Change Tracker.
Retrieving Baseline Events After the Agent Restarts
Configuring Netwrix Change Tracker to retrieve baseline events (file lists and hashes) after an agent or server restarts.
Setting Up SIEM Integration with Netwrix Change Tracker
Configuring syslog integration to forward Netwrix Change Tracker events to a Security Information and Event Management (SIEM) solution.
Turning Off Bulk Email Notifications
Shows how to configure Netwrix Change Tracker to send a separate real-time email notification for each change, instead of compiling multiple changes into a single email.
Understanding the Agent Installation Files
Describes the files stored in the Netwrix Change Tracker Gen 7 NetCore agent installation path, including Events.db, Config.xml, Rolling-log.txt, and HubDetails.xml.
Uninstalling the Change Tracker Agent via PowerShell
Uninstalling the Netwrix Change Tracker agent using the silent uninstaller executable via PowerShell for both NetCore and non-NetCore installations.
Updating Agents from the Console
Comprehensive guide for updating Netwrix Change Tracker agents from the Hub console, including download instructions, upload procedures, deployment scheduling, phased rollout strategies, testing recommendations, and troubleshooting.
Using Baseline Data Beyond Change Detection
Explains additional uses for baseline data in Netwrix Change Tracker beyond individual file change detection, including retaining full configuration records for network devices and firewalls, and points to the Baseline Center documentation for building and running a Baseline Policy.
Using Special Characters in Passwords
Supported special characters for Netwrix Change Tracker user and agent passwords, and how to configure local password requirements.
What Gen7 Objects to Monitor Using Application Performance Monitoring (APM) Tools
Recommended services, processes, paths, and log locations to monitor with application performance monitoring (APM) tools for Netwrix Change Tracker's Gen7 Hub server and agents.
Why Am I Receiving FileAccessed Events in Change Tracker?
Explains why you are receiving File Access ("fileaccessed") events in Netwrix Change Tracker, what they indicate, and how to enable or disable them via policy templates.